PaperCut customer confirmed compromise incidents
Incident
Summary
Hide ▲
Show ▼
PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immediate risk. PaperCut urged operators of Internet-exposed PaperCut Application Servers to restrict access to trusted IP addresses and deploy emergency patches. The company also shared indicators of compromise, including altered or missing server.log files and suspicious activity from pc-app.exe. The attacks remain under investigation, and the actor and post-compromise actions have not been disclosed.
Related Happenings
PaperCut NG and MF actively exploited zero-day security flaw
Vulnerability
H score26
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
About this happening:
PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk....
PaperCut NG and MF actively exploited zero-day security flaw
VulnerabilityHow related: PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
About this happening: PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk....
PaperCut emergency patches for public-facing NG/MF servers
Security Patch Release
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
PaperCut has now released emergency patches for customers with public-facing PaperCut NG/MF servers.
About this happening:
PaperCut released emergency patches for public-facing PaperCut NG/MF servers after warning that the software is under active zero-day exploitation. The patch release g...
PaperCut emergency patches for public-facing NG/MF servers
Security Patch ReleaseHow related: PaperCut has now released emergency patches for customers with public-facing PaperCut NG/MF servers.
About this happening: PaperCut released emergency patches for public-facing PaperCut NG/MF servers after warning that the software is under active zero-day exploitation. The patch release g...
Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
Vulnerability
H score49
First: 21.08.2026 09:06
Last: 21.08.2026 09:06
Sources 1
About this happening:
Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...
Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
VulnerabilityAbout this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach
Incident
H score26
First: 06.08.2026 21:22
Last: 06.08.2026 21:22
Sources 1
About this happening:
Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...
Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach
IncidentAbout this happening: Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...
Timeline
-
27.08.2026 19:31 2 articles · 3h ago
PaperCut warns of zero-day exploitation in NG and MF and releases emergency patches
Initial DisclosurePaperCut says hackers are actively exploiting a zero-day in all versions of PaperCut NG and PaperCut MF, confirms customer incidents, shares indicators of compromise including suspicious activity from the legitimate pc-app.exe process and modified, deleted, or missing server.log files, and releases emergency patches for public-facing PaperCut NG/MF servers while urging administrators to restrict Internet-exposed Application Servers to trusted IP addresses.
Show sources
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31